Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
001
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects attempts to dump credentials from the LSASS process memory, either by executing known credential dumping tools like Mimikatz, using command-line arguments indicative of credential harvesting, or performing suspicious memory access/dumping operations on the lsass.exe process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
108
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects UNC6240 PSEMHUB.war web shell/tunnel/trojanized installer artifacts by distinctive content markers (x.jsp, u.jsp, tunnel.jsp/jspx, Ple64.exe)
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects network activity (TCP, DNS, TLS, HTTP) associated with the UNC6240 threat actor's infrastructure, specifically targeting communications with known malicious IP addresses and domains used in a campaign leveraging PeopleSoft-related lures.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects network activity (TCP, DNS, TLS, HTTP) associated with the UNC6240 threat actor's infrastructure, specifically targeting communications with known malicious IP addresses and domains used in a campaign leveraging PeopleSoft-related lures.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects network activity (TCP, DNS, TLS, HTTP) associated with the UNC6240 threat actor's infrastructure, specifically targeting communications with known malicious IP addresses and domains used in a campaign leveraging PeopleSoft-related lures.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
102
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
006
Detects established, bidirectional TCP connections between internal hosts and known infrastructure associated with the SIDEEYE backdoor on specific control and data ports (3333 and 3334).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000